TwinEthosRequest access

Control

Large online platform doesn't detect/display content provenance

A large online platform must detect standards-compliant provenance data in distributed content, expose a UI disclosing whether content is GenAI-generated/captured, let users inspect provenance, and not strip provenance data.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI-generated content is not labeled, marked, or traceable as artificial · control id cond.platform-no-provenance-detection-or-display

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in California (US-CA); next date 2027-01-01.

The guard to add

Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data.

In the upload or ingest handler, read embedded provenance (c2pa.Reader, c2pa-node, @contentauth/c2pa-web, or a c2patool report) and store the result with the media record: whether credentials are present, the generating system or capture device, and signature validity. Transcoding and thumbnail steps do not strip metadata (no -strip, exiftool -all=, -map_metadata -1, piexif.remove); the signed original is kept so its manifest stays inspectable. The post or media render component shows a badge stating whether provenance is available and what it says, with an inspect panel or link to the full provenance data.

Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.

What reviewers look for: a provenance read on the ingest path before content is distributed; stored provenance fields on the media record; no metadata-stripping calls in the media pipeline; a badge component and inspect panel rendered with the content that users actually see.

Example (FastAPI + c2pa-python), before:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=file.filename, Body=data)

After:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    try:
        reader = c2pa.Reader(file.content_type, io.BytesIO(data))
        provenance = json.loads(reader.json())
    except Exception:   # no manifest or unreadable
        provenance = None
    key = f'media/{uuid.uuid4()}'
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=key, Body=data)   # original bytes, manifest intact
    db.media.insert(key=key, provenance=provenance, has_credentials=provenance is not None)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Upcoming dates

Every rule this guard addresses

Binding law — not yet in force or stayed (1)